CVE-2007-5080
Last modified
CVE-2007-5080 is a vulnerability of currently unknown severity. Integer overflow in RealNetworks RealPlayer 10 and 10.5, RealOne Player 1, and RealPlayer Enterprise for Windows allows remote attackers to execute arbitrary code via a crafted Lyrics3 2.00 tag in an MP3 file, resulting in a heap-based buffer overflow.. EPSS estimates a 7.73% chance of exploitation in the next 30 days.
Description
Integer overflow in RealNetworks RealPlayer 10 and 10.5, RealOne Player 1, and RealPlayer Enterprise for Windows allows remote attackers to execute arbitrary code via a crafted Lyrics3 2.00 tag in an MP3 file, resulting in a heap-based buffer overflow.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Realnetworks | Realone Player | 1.0 | — |
| Realnetworks | Realone Player | 2.0 | — |
| Realnetworks | Realplayer | 10.0 | — |
| Realnetworks | Realplayer | 10.5 | 6.0.12.1040 |
| Realnetworks | Realplayer Enterprise | All versions | — |
References
- http://secunia.com/advisories/27361Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/759385US Government Resource
- http://secunia.com/advisories/27361Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/759385US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5080?
How severe is CVE-2007-5080?
How do I fix CVE-2007-5080?
Are you affected by CVE-2007-5080?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
